CVE-2019-13135: High severity ibm data risk manager vulnerability
ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut.c.
Other sources
ImageMagick is vulnerable to a denial of service, caused by an uninitialized value vulnerability in the function ReadCUTImage in coders/cut.c. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-13135?
CVE-2019-13135 is a vulnerability in ImageMagick that allows a remote attacker to cause a denial of service.
How can the CVE-2019-13135 vulnerability be exploited?
The CVE-2019-13135 vulnerability can be exploited by persuading a victim to open a specially crafted file.
How severe is CVE-2019-13135?
CVE-2019-13135 has a severity rating of 8.8 (high).
Is there a patch available for CVE-2019-13135?
Yes, a patch is available for CVE-2019-13135. Please refer to the vendor's website for the patch.
Which software versions are affected by CVE-2019-13135?
ImageMagick versions before 7.0.8-50 and 6.9.10-50 are affected by CVE-2019-13135.